Commit graph

40 commits

Author SHA1 Message Date
627e61aa80 Keep emergency login visible when QR fetch fails.
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 02:04:42 +08:00
fd0df9b890 Add uds-auth zh/en i18n, UAC-branded settings, and QR expire/fail overlay.
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:10:37 +08:00
9a93e9c8ce Do not hide dsh-ops-cron task rows with the session-only projectRow CSS.
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 16:03:42 +08:00
c41991057d Restore workspace partitions for super admins; only force flat after auth-ready.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:17:18 +08:00
e9040224fb Force flat session sidebar for users without workspace create.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:57:23 +08:00
1b397c6733 Unblock composer for normal QR users after login.
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:45:52 +08:00
6b24fd15da Use soft reconnect on logout instead of full page reload.
Hard reload stays only after login so Set-Cookie is committed before WS upgrade.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:36:35 +08:00
97dbfc4940 Reload after login so session history keeps WS identity.
Soft reconnect raced Set-Cookie and left session.page unauthenticated while prompt still worked.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:10:15 +08:00
1053403d88 Prefer soft reconnect after UDS login instead of full reload.
Workspace ACL no longer depends on a hard refresh; keep reload only as fallback.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:45:07 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
337f6501b0 Enable fallback_admin by default with Admin@123.
Initial deploys often cannot scan UAC QR; seed the emergency account unless roles.json explicitly disabled it.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:09:14 +08:00
6455feed65 Fix fallback_admin logout so badge returns to 未登录.
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:58:47 +08:00
ed562f7c21 Fix anonymous blank UI and stale session restore.
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:51:08 +08:00
d0f77d2d4e Clear restored session when UDS user is anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:41:02 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
7d4d228317 Clear UDS_FALLBACK_UI cookie on logout. 2026-09-08 10:29:09 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
42c5dd2c35 Simplify footer auth badge to username and anchor panel above it.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:17:30 +08:00
cf5c9d5060 Reconnect remote.mux after UDS login so session history uses new cookies.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:10:37 +08:00
1f2ff7e00b Block inert composer card clicks unless super_admin.
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:25:43 +08:00
1fc39a3210 Gate open-workspace UI to super_admin only.
Non-super users keep their auto-provisioned workspace; hide Choose workspace and keep the picker locked unless canCreateWorkspace is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:22:15 +08:00
52fc39f71e Lock workspace chooser for anonymous users before first click.
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:13:03 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
9d16301700 Match UDS login chrome to Settings trigger; sit login near sidebar edge.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:00:29 +08:00
1ac1aec952 Lay Settings and UDS login on one sidebar foot row side by side.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:54:08 +08:00
e052ef4bf4 Pin UDS login to sidebar.footer.action (stable foot next to Settings, right-aligned).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:50:19 +08:00
7e2d8ef5d8 Avoid login badge overlapping Session log: header when in session, overlay only when idle.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:44:12 +08:00
705c6864ef Show UDS login on shell.overlay so it is visible without an active session.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:39:58 +08:00
8f569070a0 Remove broken /settings shortcut from UDS login badge panel.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:34:25 +08:00
b3b5b6997e Fix first-login bootstrap to super_admin; allow admin settings via canAccessSettings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:23:20 +08:00
74a86ff832 Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:37:08 +08:00
b535714000 Move UDS login into header.utilities so it sits left of session log-download.
EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:22:43 +08:00
91a1804f68 Place UDS login beside session log-download in the same header.actions slot. 2026-09-08 02:17:17 +08:00
b4fa832a6b Move UDS login back to top-right overlay, docked left of toggles with matching chrome style. 2026-09-08 02:13:25 +08:00
6caafe9590 Fix uds-auth client.js syntax error that broke the whole plugin bundle. 2026-09-08 02:00:55 +08:00
6360f80349 Move UDS login badge into session header actions to avoid covering Search/toggles. 2026-09-08 01:58:31 +08:00
505f9dea3f Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00